Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-5674


Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.


Published

2020-11-24T07:15:11.937

Last Modified

2024-11-21T05:34:27.477

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.4

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-427

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application epson album_print - Yes
Application epson color_calibration_utility - Yes
Application epson colorbase - Yes
Application epson colorio_easy_print - Yes
Application epson connect - Yes
Application epson creativity_suite - Yes
Application epson e-photo - Yes
Application epson e-photo - Yes
Application epson easy_photo_print - Yes
Application epson easy_photo_print - Yes
Application epson easy_settings - Yes
Application epson imaging_workshop - Yes
Application epson link2 - Yes
Application epson multi-print_quicker - Yes
Application epson net_config - Yes
Application epson net_config_se - Yes
Application epson net_print - Yes
Application epson net_software_development_kit - Yes
Application epson photolier - Yes
Application epson photoquicker - Yes
Application epson photostarter 3.1 Yes
Application epson pm-t990_integrated_installer - Yes
Application epson print - Yes
Application epson print - Yes
Application epson print - Yes
Application epson print_image_framer_tool - Yes
Application epson print_layout - Yes
Application epson prolab_print - Yes
Application epson prolab_print - Yes
Application epson remote_printer_driver - Yes
Application epson scan_icm_updater - Yes
Application epson scanner_driver - Yes
Application epson web_to_page - Yes
Application epson webconfig - Yes
Application epson universal_print_driver - Yes
Operating System microsoft windows - No
Operating System microsoft windows - No
Application epson status_monitor_2 - Yes
Application epson status_monitor_3 - Yes
Operating System microsoft windows - No
Operating System epson ec-01_firmware - Yes
Hardware epson ec-01 - No
Application epson print_image_framer_tool - Yes
Operating System microsoft windows_98 - No
Operating System microsoft windows_me - No

References